Privacy Policy
Last updated 2 October 2026
This policy describes what we collect, why, who else sees it, and what you can ask us to do about it. It is written to be read, not to be survived.
1. Who is responsible
The data controller is Sistemik SpA (RUT 78.493.576-0), Santiago, Chile. Privacy contact: hello@aeviamodeler.ai.
2. What we collect
Account data. Your email address, a hashed password, your display name if you set one, and your plan and subscription status. We need this to give you an account.
Content you create. Your chats, product systems, assessments, comparisons, analyses, reports, workspaces, and any documents you upload to your knowledge base. We store this so the Service works; it is yours.
Connection details. If you connect your own openLCA, we store the connection's name and network details and, for a tunnelled connection, an authentication token for the connector app. We do not store a copy of your database.
Connecting from an AI assistant. If you connect Aevia to an
assistant such as Claude or ChatGPT through the MCP connector, we keep a record of
each connection: its name, the access tier you approved, the workspace and database
it works with, when it was last used, and a hashed form of its access credentials,
never the credentials themselves. An assistant that registers itself with us leaves
a client record (the application's name and the address it returns you to after
sign-in); a record that is never used is deleted after 7 days. When an assistant
connects, it also reports the name and version of its own software (for example
claude-ai/1.0); we record that, and which of Aevia's built-in
playbooks it loads, so we can see which assistants our users work from and which
guidance they read. These usage records are deleted after 180 days. When the assistant
searches the knowledge library, we also keep the text of each search and whether it
found anything, so we can investigate problems with search results; these search
records are deleted after 30 days. What the assistant asks Aevia to build or calculate
is saved to your workspaces like any other content you create.
Usage and cost records. Per-request records of model, token counts and cost, so we can meter credits and show you what a conversation spent. These are tied to your account.
Technical logs. IP address, user agent, request identifiers, timestamps and errors. Used for security, abuse prevention and debugging.
Diagnostic records of model requests. While Aevia is in early access, we keep a complete record of each request the assistant in the app makes to a language model: what was sent to it (its instructions and the conversation so far) and what it answered. We use these records only to investigate when something goes wrong, and they are deleted after 30 days, or sooner if you delete the chat.
Payment data. Handled by Paddle, not by us. We receive a transaction reference, the amount, and your subscription status. We never see or store your card details.
Where you came from. When you create an account we store
on it where the visit that led to it came from: the campaign marker on the
link you followed, if it had one (?src= or the usual
utm_ parameters), and the hostname of the site that
linked you to us, which our pages carry along until you sign up. If you create
the account while connecting Aevia to an AI assistant, we also record that, and
which assistant it was, by the web address it uses to receive the connection
(for example claude.ai). It tells us which channels our users
actually come from. We never keep the full address of the referring page —
only the hostname — and we do not record any of this for people who do not
create an account.
Visit statistics. On these marketing pages we count visits using analytics software we run ourselves, on our own server. It records the page viewed, the site that linked you here, and your browser, operating system, screen size and country. It sets no cookies, does not store your IP address, and cannot follow you to any other website. To count repeat visits within a day it uses a value derived from your IP address and browser that is discarded and re-derived daily, so it cannot be used to recognise you tomorrow. The application itself, once you sign in, is not tracked this way.
We do not use advertising trackers, and there is no third-party analytics or advertising cookie on this website. The statistics above are collected by software running on our own server and are never sent to an analytics company; the marker described earlier is likewise stored only by us.
3. Why we may process it, lawfully
- To perform our contract with you — running the Service, your account, and billing.
- Our legitimate interests — keeping the Service secure, preventing abuse and fraud, and improving reliability, balanced against your rights.
- Legal obligation — tax and accounting records.
- Consent — where we ask for it, such as optional product email. You can withdraw it at any time.
4. Who else processes it
To operate, we send parts of a request to service providers acting on our instructions. Each receives only what its task requires.
- Large-language-model providers — Anthropic, OpenAI, Google and other model providers we route to. They receive the conversation content needed to generate a response, which can include the LCA entity names and figures under discussion. Our agreements with them prohibit using your content to train their models.
- Embedding provider — OpenAI receives the text of knowledge-library searches, and of documents added to the library, to index and search them.
- Web-search provider — receives your search query when you use the assistant's web search.
- Paddle — payment processing and merchant of record; receives what it needs to take payment and issue an invoice.
- Email provider — receives your address to deliver verification, password-reset and account mail.
- Hosting provider — Hetzner Online GmbH, Nuremberg, Germany, where the application and database run.
- Error monitoring — Sentry, which receives a report when something goes wrong: the error and its stack trace, the page or endpoint involved, your browser and, where we know it, the account id of whoever hit it. It exists so we find out something is broken without waiting for you to tell us. We do not record your screen or your keystrokes, and conversation content is not sent.
- The assistant you connect — when you use the MCP connector, the results of the requests you make through it are returned to the assistant you chose, such as Claude or ChatGPT. Its provider handles them under its own terms and privacy policy; it is not a processor of ours.
We do not sell personal data, and we do not share it for advertising. We may disclose data where legally required, and will tell you unless prohibited.
5. Where your data lives, and transfers
The application and its database are hosted in Germany (EU). Some providers above process data elsewhere, including the United States. Where a transfer leaves the EEA we rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard.
6. How long we keep it
Content you create is yours and stays until you delete it. Everything we keep only to run, secure or fix the Service is kept for a set period and then deleted; the periods are listed here.
- Account and content — while your account exists. Delete your account and we delete them, except as below.
- Assistant connections — kept while your account exists, including connections you have disconnected or that have expired, and deleted with your account. The access an assistant receives lasts an hour at a time and can be renewed for up to 90 days, after which it asks you to approve it again. An access key expires after the period chosen when it was created, 90 days by default.
- Assistant usage records — which assistant software connected and which playbooks it loaded: 180 days.
- Knowledge-library searches made by an assistant — the search text and whether it found anything: 30 days.
- Backups — encrypted database backups are deleted after 90 days, so deleted content can persist in them for up to 90 days.
- Billing records — retained as long as tax law requires, typically 6 years.
- Diagnostic records of model requests — 30 days, or until you delete the chat, whichever comes first.
- Copies of processes and flows you delete from your own openLCA database through Aevia — kept 30 days so you can restore them, then deleted.
- Technical logs — deleted after 180 days at most.
- Signup-credit records — we keep a minimal record that an account received its one-time credit, so it cannot be claimed repeatedly. This survives account deletion by necessity.
7. Your rights
Depending on where you live you may have the right to access, correct, delete, restrict or object to our processing of your personal data, and to receive it in a portable format. Chilean law (Ley 19.628, as amended) and, where it applies to you, the GDPR both give rights of this kind.
To exercise any of them, write to hello@aeviamodeler.ai. We will respond within 30 days. You can also complain to your local data-protection authority.
8. Security
Traffic is encrypted in transit with TLS. Passwords are hashed, never stored in a readable form. Credentials you give us for a third-party service — provider API keys, engine connections — are encrypted at rest. Access to production data is limited to those who need it to operate the Service. Databases are backed up encrypted.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority as the law requires.
9. Cookies
The application uses cookies and local storage strictly to keep you signed in, to remember interface preferences, and to finish connecting an AI assistant while you confirm your email address (that note is deleted after an hour). There are no advertising or cross-site-tracking cookies, and this marketing website sets no cookies at all.
10. Children
The Service is not directed at children and is not for anyone under 18. We do not knowingly collect their data; if we learn we have, we delete it.
11. Changes
We may update this policy. Material changes are announced by email at least 30 days ahead. The date at the top always reflects the current version.